Vulnerabilities

Summary — last 7 days

New vulnerabilities2,743▼ 518 vs. last week
Critical / high1,293▼ 226 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)244▼ 258 vs. last week
–

215 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.5)0.51%—Creatives Planet GreenlyAI3/13/20266/17/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly greenly allows PHP Local File Inclusion.This issue affects Greenly: from n/a through <= 8.1.
DeferredMedium (6.4)0.27%—Creativethemes BlocksyAI3/2/20266/17/2026
The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in all versions up to, and including, 2.1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
DeferredLow (3.8)0.24%—Creativeinteractivemedia Real 3D FlipbookAI2/19/20266/17/2026
Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.19.1.
DeferredMedium (5.9)0.24%—Creativemindssolutions CM Business DirectoryAI2/19/20266/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Business Directory cm-business-directory allows Stored XSS.This issue affects CM Business Directory: from n/a through <= 1.5.3.
AnalyzedMedium (6.1)0.28%—Creativeitem Academy LMS2/3/20266/17/2026
Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the string parameter to the /academy/course_bundles/search/query endpoint. These vulnerabilities are distinct from the patch for CVE-2023-4119, which only fixed XSS in…
DeferredMedium (6.5)0.17%—Creativeinteractivemedia Real3d-flipbook-liteAI12/24/202510/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Stored XSS.This issue affects Real 3D FlipBook: from n/a through <= 4.11.4.
DeferredMedium (4.3)0.22%—Creativemindssolutions CM ON Demand Search AND ReplaceAI12/16/202510/7/2026
Missing Authorization vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-replace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM On Demand Search And Replace: from n/a through <= 1.5.5.
AnalyzedMedium (5.1)0.25%—Creativeitem Academy LMS12/15/20256/17/2026
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
AnalyzedMedium (5.5)0.18%—Adobe Creative Cloud12/9/20259/25/2026
Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to disrupt the application's functionality by manipulating temporary…
DeferredMedium (4.3)0.18%—Essentialplugin Featured Post CreativeAI11/21/20256/17/2026
Missing Authorization vulnerability in Essential Plugin Featured Post Creative featured-post-creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through <= 1.5.5.
DeferredHigh (8.8)0.69%—Creativethemes Blocksy CompanionAI11/11/20256/17/2026
The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to insufficient file type validation detecting SVG files, allowing double extension files to bypass sanitization while being accepted as a valid SVG file. This makes…
DeferredHigh (8.1)0.52%—Creatives Planet LeblixAI11/6/202510/7/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Leblix leblix allows PHP Local File Inclusion.This issue affects Leblix: from n/a through <= 2.4.
DeferredMedium (6.4)0.20%—Creativethemes Blocksy CompanionAI10/30/20256/17/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsletter_subscribe' shortcode in all versions up to, and including, 2.1.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalyzedMedium (5.6)0.14%—Adobe Creative Cloud10/15/20256/17/2026
Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing between the check and use of a resource, potentially allowing unauthorized…
AnalyzedCritical (9.4)0.47%—Creativeitem Academy LMS10/15/20256/17/2026
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.
AnalyzedMedium (6.4)0.22%—Creativeitem Academy LMS10/15/20256/17/2026
Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.
AnalyzedLow (2.2)0.16%—Creativeitem Academy LMS10/15/20256/17/2026
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
AnalyzedMedium (6.5)0.29%—Creativeitem Academy LMS10/14/20256/17/2026
Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instructor-only functions without proper role validation, allowing unauthorized course creation and management.
DeferredMedium (5.1)0.36%—Creativeitem SocioproAI10/2/20256/17/2026
Stored XSS vulnerability in Creativeitem Sociopro due to lack of proper validation of user inputs via the endpoint '/sociopro/profile/update_profile', affecting to 'name' parameter via POST. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal his/her cookie…
AnalyzedMedium (5.1)0.21%—Creativeitem Ekushey Project Manager CRM10/2/20256/17/2026
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_file/upload/xxxx", affecting to "description" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query…
AnalyzedMedium (5.1)0.21%—Creativeitem Ekushey Project Manager CRM10/2/20256/17/2026
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to "message" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an…
AnalyzedMedium (5.1)0.21%—Creativeitem Ekushey Project Manager CRM10/2/20259/30/2026
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_bug/create/xxx", affecting to "title" and "description" parameters via POST. This vulnerability could allow a remote attacker to send a specially…
DeferredMedium (6.4)0.25%—Creativethemes Blocksy CompanionAI9/17/20256/17/2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
DeferredCritical (9.3)0.34%—Prebid Universal CreativeAIPrebid.jsAI9/9/20256/17/2026
Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This includes the extremely popular jsdelivr hosting of this file. The maintainers of PUC unpublished version 1.17.3. Users should see Prebid.js 9…
DeferredHigh (7.1)0.24%—Creativemedia Elite Video PlayerAI8/20/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Reflected XSS.This issue affects Elite Video Player: from n/a through <= 10.0.5.
Orbitaley — Vulnerabilities